How to Control JavaScript's Strict Mode
jskatas.org
jskatas.org
https://developer.mozilla.org/en-US/docs/Web/JavaScript/Refe...
This affects V8's stack frames as well [1]. Is this related to the principle of least privilege? Can someone explain what specific vulnerability could result from allowing "secured code to access privileged functions and their (potentially unsecured) arguments" in Javascript?
> The "use strict" directive can only be applied to the body of functions with simple parameters. Using "use strict" in functions with rest, default, or destructured parameters is a syntax error.
function sum(a = 1, b = 2) {
// SyntaxError: "use strict" not allowed in function with default parameter
"use strict";
return a + b;
}
Not that I would see myself doing this, I would put strict mode in a function containing all the code of the file that does not take any argument (or maybe dependencies), but why would "use strict"; be forbidden here?A bit hard to understand this transcript without context but it really reads like SpiderMonkey and Chakra were actually able to parse this. V8 people didn't like it, the others were like "ok, whatever" and they ended up disallowing it in the spec.
I guess it allows simplifications in the parsers by not having a "strict or sloppy, don't know" mode for default parameter values, while not blocking actual use cases.
I thought that parsing completed before execution, so why couldn’t the parser generate the same AST for these two functions?
(a) => a === undefined ? 1 : a
(a = 1) => a
Actually, yes. default parameter values could contain things that are allowed in sloppy mode and are syntax errors in strict mode. For instance, a leading zero in numbers without explicitly specifying the base, duplicate property names, the with statement, new reserved words and using delete on a variable name.
You need to disallow those in the parameter values in strict mode, but you only know this after encountering the "use strict" marking in the function body if you were not already in strict mode. You can make a parser able to do this, but it is more complex. I guess they decided that this complexity is not worth it.
As a beginner, I remember finding this magical literal that (might) alter JS behavior pretty strange, especially since there were no other `use` directives.
I really like Perl's `use diagnostics` directive, which provides more verbose error messages, and am frankly surprised a far more popular language that is supposed to be beginner-friendly does not have something similar.
The first time, it gave jQuery, which notably inherited the $ and the terser syntax from perl. The second time, indeed, JS found Perl's "use strict" quite cute.
[1] https://web.archive.org/web/20150525070848/https://mail.mozi...
Probably irrelevant today.